
At a glance
The estate
Profile
Software platform
50,000+ businesses
100M+ end users
Environment
25+ AWS accounts
a Snowflake warehouse fed by 40+ systems
Google Workspace
Microsoft 365
a multi-petabyte S3 store
The challenge
Proving PCI compliance at petabyte scale
A new PCI control demanded proof that no unknown caches of credit-card data were hiding anywhere in the estate, and the Company couldn't give it.
Legacy brute-force scanning was financially out of reach at this scale; a single pass of the S3 store alone was estimated at $200,000.
There was no single lens on the data, and no clear owner for whatever a scan surfaced.
“Your operator might have just taken a screenshot of her credit card number… I can’t tell you how many times that has actually happened, and it’s hiding inside that S3 bucket.”
Director of Data & Analytics Engineering
Why Bedrock Data
Data Security built for depth and cost
A serverless Outpost with Zero Data Access
Ephemeral functions classify data locally inside the Company's environment; only anonymized metadata leaves the boundary, and databases are side-scanned from snapshots so production is never touched.
Adaptive Scanning instead of brute force scanning
Intelligent sampling across the estate, with selective full scans reserved for the highest-risk targets, so the Company ran its entire first phase at a small fraction of the cost of one legacy scan.
AI-driven classification and entitlement analysis
Classifies by meaning rather than pattern-matching to cut false positives, and maps the access chain for every identity to show who can actually reach sensitive data.
A unified metadata lake
A graph-based system of record with lineage that traces where sensitive data travels, built without storing customer data.
Results
What the scan surfaced
OCR-based scanning crawled roughly 300 million files and estimated 25,000 containing card data, turning an unbounded fear into a bounded number.
Sensitive PII surfaced in employees' personal cloud drives across both Google Workspace and Microsoft 365.
Finding sensitive data became a repeatable scan instead of a multi-team hunt.
Effective-access visibility resolved the nested, chained roles that make Snowflake hard to reason about, exposing access no permissions list would show.
Exposed credentials were found stored in places they shouldn't have been, and a third-party integration held more standing access to a confidential shared drive than anyone had realized.
The vision
What success looks like, in the CIO's words
“Full org adoption. Our internal processes nailed down, our rule sets configured, our owners with their processes dialed in. And when there are findings, those create tickets, the right team gets it, they own the resolution, and it all works together. That’s what success looks like.”
CIO
What's next
The roadmap turns toward action
A distributed ownership model in which each domain has an owner accountable for remediation: data engineering for Snowflake, IT for SaaS and Microsoft 365, infrastructure teams for RDS.
Leaner PCI: automated discovery and classification engineered to cut audit-prep cycles by 50 to 70 percent and reduce PCI scope, with Adaptive Scanning targeting 10 to 100 times lower scanning TCO than brute-force approaches.
Automated, closed-loop remediation that routes each finding to the right team and re-validates the fix in the source system.
Governed AI and least-privilege access that protect sensitive data without slowing data science.
Identity resolution that ties disparate records to single identities, which could right-size cyber-insurance premiums.
